Here is the log
ComboFix 09-01-02.01 - Compaq_Owner 2009-01-04 14:07:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.131 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\New Folder\ark.exe
AV: Norton Internet Security *On-access scanning enabled* (Updated)
AV: avast! antivirus 4.8.1296 [VPS 090103-0] *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Compaq_Owner\Application Data\inst.exe
c:\windows\k.txt
c:\windows\system32\~.exe
c:\windows\system32\au3305adc.dll
c:\windows\system32\av.exe
c:\windows\system32\drivers\TDSSmaxt.sys
c:\windows\system32\getwn32.dll
c:\windows\system32\TDSScfub.dll
c:\windows\system32\TDSSfxmp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\wertyu.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 )))))))))))))))))))))))))))))))
.
2009-01-03 21:02 . 2009-01-03 22:37 d——– c:\documents and settings\Compaq_Owner\DoctorWeb
2009-01-02 16:23 . 2005-05-16 17:37 d——– c:\documents and settings\Administrator\WINDOWS
2009-01-02 16:23 . 2005-05-16 18:01 d——– c:\documents and settings\Administrator\Application Data\Symantec
2009-01-02 16:23 . 2005-05-16 17:52 d——– c:\documents and settings\Administrator\Application Data\SampleView
2009-01-02 16:23 . 2005-05-16 17:57 d——– c:\documents and settings\Administrator\Application Data\InterMute
2009-01-02 16:23 . 2005-05-16 17:36 d——– c:\documents and settings\Administrator\Application Data\Apple Computer
2009-01-02 16:23 . 2009-01-04 11:32 d——– c:\documents and settings\Administrator
2009-01-02 14:54 . 2004-08-04 00:56 116,224 –a—— c:\windows\system32\dllcache\xrxwiadr.dll
2009-01-02 14:54 . 2001-08-17 22:37 27,648 –a—— c:\windows\system32\dllcache\xrxftplt.exe
2009-01-02 14:54 . 2001-08-17 22:36 23,040 –a—— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-01-02 14:54 . 2001-08-17 22:36 17,408 –a—— c:\windows\system32\dllcache\xrxscnui.dll
2009-01-02 14:54 . 2001-08-17 22:37 4,608 –a—— c:\windows\system32\dllcache\xrxflnch.exe
2009-01-02 14:52 . 2001-08-17 13:28 765,884 –a—— c:\windows\system32\dllcache\usrti.sys
2009-01-02 14:51 . 2001-08-17 13:28 794,654 –a—— c:\windows\system32\dllcache\usr1801.sys
2009-01-02 14:50 . 2001-08-17 22:36 525,568 –a—— c:\windows\system32\dllcache\tridxp.dll
2009-01-02 14:49 . 2004-08-04 07:00 571,392 –a—— c:\windows\system32\dllcache\tintlgnt.ime
2009-01-02 14:48 . 2001-08-17 12:18 285,760 –a—— c:\windows\system32\dllcache\stlnata.sys
2009-01-02 14:47 . 2001-08-17 14:56 147,200 –a—— c:\windows\system32\dllcache\smidispb.dll
2009-01-02 14:46 . 2004-08-03 22:41 404,990 –a—— c:\windows\system32\dllcache\slntamr.sys
2009-01-02 14:45 . 2001-08-17 22:36 495,616 –a—— c:\windows\system32\dllcache\sblfx.dll
2009-01-02 14:44 . 2004-08-04 00:56 397,056 –a—— c:\windows\system32\dllcache\s3gnb.dll
2009-01-02 14:43 . 2001-08-17 13:28 899,146 –a—— c:\windows\system32\dllcache\r2mdkxga.sys
2009-01-02 14:42 . 2004-08-04 07:00 482,304 –a—— c:\windows\system32\dllcache\pintlgnt.ime
2009-01-02 14:41 . 2004-08-04 00:56 259,328 –a—— c:\windows\system32\dllcache\perm3dd.dll
2009-01-02 14:40 . 2004-08-04 00:56 4,274,816 –a—— c:\windows\system32\dllcache\nv4_disp.dll
2009-01-02 14:39 . 2004-08-03 22:31 132,695 –a—— c:\windows\system32\dllcache\netwlan5.sys
2009-01-02 14:38 . 2004-08-04 00:56 1,737,856 –a—— c:\windows\system32\dllcache\mtxparhd.dll
2009-01-02 14:37 . 2004-08-04 07:00 1,875,968 –a—— c:\windows\system32\dllcache\msir3jp.lex
2009-01-02 14:36 . 2004-08-04 07:00 1,158,818 –a—— c:\windows\system32\dllcache\korwbrkr.lex
2009-01-02 14:35 . 2004-08-04 07:00 471,102 –a—— c:\windows\system32\dllcache\imskdic.dll
2009-01-02 14:34 . 2004-08-04 07:00 811,064 –a—— c:\windows\system32\dllcache\imjp81k.dll
2009-01-02 14:33 . 2004-08-04 07:00 13,463,552 –a—— c:\windows\system32\dllcache\hwxjpn.dll
2009-01-02 14:32 . 2001-08-17 14:56 1,733,120 –a—— c:\windows\system32\dllcache\g400d.dll
2009-01-02 14:31 . 2001-08-17 12:15 455,680 –a—— c:\windows\system32\dllcache\fus2base.sys
2009-01-02 14:30 . 2001-08-17 13:28 634,134 –a—— c:\windows\system32\dllcache\el656ct5.sys
2009-01-02 14:29 . 2001-08-17 12:14 952,007 –a—— c:\windows\system32\dllcache\diwan.sys
2009-01-02 14:28 . 2004-08-04 07:00 1,677,824 –a—— c:\windows\system32\dllcache\chsbrkr.dll
2009-01-02 14:27 . 2001-08-17 13:28 871,388 –a—— c:\windows\system32\dllcache\bcmdm.sys
2009-01-02 14:26 . 2004-08-04 00:56 1,888,992 –a—— c:\windows\system32\dllcache\ati3duag.dll
2009-01-02 14:25 . 2001-08-17 13:28 762,780 –a—— c:\windows\system32\dllcache\3cwmcru.sys
2009-01-02 14:25 . 2001-08-17 14:55 689,216 –a—— c:\windows\system32\dllcache\3dfxvs.dll
2009-01-02 14:25 . 2001-08-17 22:36 462,848 –a—— c:\windows\system32\dllcache\a3dapi.dll
2009-01-02 14:25 . 2004-08-03 22:32 231,552 –a—— c:\windows\system32\dllcache\ac97ali.sys
2009-01-02 14:25 . 2001-08-17 12:48 148,352 –a—— c:\windows\system32\dllcache\3dfxvsm.sys
2009-01-02 14:25 . 2001-08-17 22:36 98,304 –a—— c:\windows\system32\dllcache\a3d.dll
2009-01-02 14:25 . 2001-08-17 14:56 66,048 –a—— c:\windows\system32\dllcache\s3legacy.dll
2009-01-02 14:25 . 2004-08-03 23:10 48,128 –a—— c:\windows\system32\dllcache\61883.sys
2009-01-02 14:25 . 2001-08-17 14:55 38,400 –a—— c:\windows\system32\dllcache\8514a.dll
2009-01-02 14:25 . 2001-08-17 13:52 23,552 –a—— c:\windows\system32\dllcache\abp480n5.sys
2009-01-02 14:25 . 2004-08-03 23:00 12,288 –a—— c:\windows\system32\dllcache\4mmdat.sys
2009-01-02 14:25 . 2001-08-17 14:06 11,264 –a—— c:\windows\system32\dllcache\1394vdbg.sys
2008-12-26 12:19 . 2008-12-26 12:19 d——– c:\documents and settings\NetworkService\Application Data\Webroot
2008-12-16 23:06 . 2008-12-16 23:06 d——– c:\program files\Webroot
2008-12-16 23:06 . 2008-12-16 23:06 d——– c:\documents and settings\Compaq_Owner\Application Data\Webroot
2008-12-16 23:06 . 2004-02-11 18:27 102,912 –a—— c:\windows\system32\islzma.dll
2008-12-16 23:06 . 2006-01-25 10:54 78,336 –a—— c:\windows\system32\drivers\ssi.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 17:02 ——— d—–w c:\program files\PeerGuardian2
2009-01-02 00:55 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\OpenOffice.org2
2009-01-01 01:08 9,476 —-a-w c:\documents and settings\Compaq_Owner\Application Data\wklnhst.dat
2008-12-16 15:23 ——— d—–w c:\program files\Mozilla Thunderbird
2008-12-15 18:15 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\U3
2008-12-12 17:27 3,067,392 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-11-25 21:24 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-11-14 19:54 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-07 23:34 ——— d—–w c:\program files\Shockwave.com
2008-11-07 23:33 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-07 22:26 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\iWin
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 16:57 332,800 —-a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 14:18 18,432 —-a-w c:\windows\system32\dllcache\iedw.exe
2008-05-15 21:48 47,360 —-a-w c:\documents and settings\Compaq_Owner\Application Data\pcouffin.sys
2008-01-04 21:57 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-11-30 14:51 67,696 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-11-30 14:51 54,376 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-11-30 14:51 34,952 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-11-30 14:51 46,720 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-11-30 14:51 172,144 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-08-27 58488]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-16 282624]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\ark.exe" [2006-01-25 3405312]
"SiSPower"="SiSPower.dll" [2005-04-12 c:\windows\system32\SiSPower.dll]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 c:\windows\sm56hlpr.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\c:\
0autocheck autochk *\
0SsiEfr.e\
0SsiEfr.e
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
–a—— 2007-11-20 16:40 731136 c:\program files\dvd43\DVD43_Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a–c— 2004-07-28 01:50 221184 c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 18:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-12-16 09:32 282624 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Total War\\Medieval - Total War\\Medieval_TW.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\GigaTribe\\gigatribe.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 SSI;SSI;c:\windows\system32\drivers\ssi.sys [2008-12-16 78336]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-09 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-09 20560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9dcfda2-09e1-11da-b1f9-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
*Newly Created Service* - PROCEXP90
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add To Compaq Organize… - c:\progra~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\k1fomxfs.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-04 14:09:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmaxt.sys"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(568)
c:\windows\system32\WRLogonNTF.dll
.
Completion time: 2009-01-04 14:10:34
ComboFix-quarantined-files.txt 2009-01-04 19:10:15
Pre-Run: 57,452,032,000 bytes free
Post-Run: 57,468,440,576 bytes free
219 — E O F — 2008-12-26 17:33:37